Malicious PDF — malware analysis report

Static analysis result for SHA-256 e5162600a7413925…

MALICIOUS

PDF

23.7 KB Created: 2019-04-30 08:29:08 +01:00 Authoring application: mPDF 5.7
MD5: c6ccd174182ddb5ca4afe6724dda277f SHA-1: 9408a975c2b0c3aad7be70110bf7040c54e65903 SHA-256: e5162600a74139251ae1712ed7eaca72bc5419a55a36a2b2a0969a1ae9af3dea
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF was flagged by a critical heuristic for containing a mass external link farm, with 29 links detected. While most individual URLs were marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO poisoning or to mask malicious redirects. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/14e14e34e34e84e04e8/Gone-Walkabout-in-Henn-Boo-Too-by-William-P-Hogan.pdf
    • http://unieoooq.linkpc.net/14e14e34e34e84e04e7/Henn-on-Copyright-Law-A-Practitioner-s-Guide-by-Harry-G-Henn.pdf
    • http://unieoooq.linkpc.net/14e14e34e34e94e54e4/The-Honor-of-My-Brothers-A-Brief-History-of-the-Relationship-Between-the-Pope-and-the-Bishops-by-William-Henn.pdf
    • http://unieoooq.linkpc.net/74e94e34e04e44e3/Richelieu-and-Reason-of-State-by-William-Farr-Church.pdf
    • http://unieoooq.linkpc.net/34e34e94e94e24e0/The-Theology-And-Spirituality-of-Mary-Tudor-s-Church-by-William-Wizeman.pdf
    • http://unieoooq.linkpc.net/94e44e74e14e54e7/The-Bohlen-Lectures-for-1891-the-Peace-of-the-Church-by-William-Reed-Huntington.pdf
    • http://unieoooq.linkpc.net/74e64e14e34e74e0/Curlew-River----A-Parable-for-Church-Performance-Op-71-Libretto-by-William-Plomer.pdf
    • http://unieoooq.linkpc.net/14e04e04e04e64e5/The-Founding-Moment-Church-Society-and-the-Construction-of-Trinity-College-by-William-Westfall.pdf
    • http://unieoooq.linkpc.net/64e64e94e54e54e4/Historical-sketch-of-Bruton-church-Williamsburg-Virginia-by-William-Archer-Rutherford-Goodwin.pdf
    • http://unieoooq.linkpc.net/64e64e94e44e54e0/Historical-Sketch-of-Bruton-Church-Williamsburg-Virginia-by-William-Archer-Rutherford-Goodwin.pdf
    • http://unieoooq.linkpc.net/74e04e94e84e44e1/The-Manifesto-Church-Records-of-the-Church-in-Brattle-Square-Boston-With-Lists-of-Communicants-Baptisms-Marriages-and-Funerals-1699-1872-by-Church-in-Brattle-Square-Boston.pdf
    • http://unieoooq.linkpc.net/24e74e04e24e74e1/Light-Your-Church-On-Fire-Without-Burning-It-Down-Church-In-The-21st-Century-by-David-Housholder.pdf
    • http://unieoooq.linkpc.net/44e64e14e34e8/The-Book-of-Common-Prayer-and-Administration-of-the-Sacraments-and-Other-Rites-and-Ceremonies-of-the-Church-by-Church-of-England.pdf
    • http://unieoooq.linkpc.net/74e04e84e84e14e1/The-Church-of-God-or-Essays-on-Various-Names-and-Titles-Given-to-the-Church-in-the-Holy-Scriptures-To-Which-Are-Added-Some-Papers-on-Other-Subjects-by-Ambrose-Serle.pdf
    • http://unieoooq.linkpc.net/74e04e84e84e14e2/The-Church-of-God-Or-Essays-on-Various-Names-and-Titles-Given-to-the-Church-in-the-Holy-Scriptures-To-Which-Are-Added-Some-Papers-on-Other-Subjects-by-Ambrose-Serle.pdf
    • http://unieoooq.linkpc.net/14e14e34e34e74e34e0/AGASAGASAGA01KUBINASHIRAITA-HENN-by-KONAMINAKO.pdf
    • http://unieoooq.linkpc.net/14e14e04e34e74e74e0/Where-Bear-by-Sophy-Henn.pdf
    • http://unieoooq.linkpc.net/14e14e04e44e04e74e3/Pom-Pom-the-Champion-by-Sophy-Henn.pdf
    • http://unieoooq.linkpc.net/14e14e34e34e94e44e0/The-Bible-As-Literature-by-T-R-Henn.pdf
    • http://unieoooq.linkpc.net/14e14e34e34e84e44e9/They-re-Watching-Over-You-by-Eric-Henn.pdf
    • http://unieoooq.linkpc.net/